Drift Boss Original
acfjniffcmahollkfpmbafogeknigieg
Risk Score
5.41
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL unreachable (fetch_error) — effectively no privacy policy disclosed.
- 31 months without update — zombie extension with active installs.
- Uninstall URL hijack + install URL hijack redirecting to drift-boss.me on install.
- Free-webmail dev (gmail), no developer name, no verified publisher — identity unverifiable.
- Sandbox CSP uses unsafe-eval and unsafe-inline enabling script execution in sandboxed pages.
Evidence
- uninstall_url_hijack + install_url_hijack crx onInstalled opens https://drift-boss.me/#welcome; uninstall URL also hijacked — Webstore +3.0+2.0.
- privacy_policy_fetch_error crx games777.io/privacy-policy/ returned ConnectionError — treated as fetched==false → Privacy +10.0.
- free_webmail_no_dev_name store Developer johnkarik2023@gmail.com, no developer_name — Reputation floor 7.5 (free-webmail + no name).
- months_since_update_31 store 31 months since last update → Maintenance +8.5 (24-36mo band).
- sandbox_unsafe_eval crx Sandbox CSP includes unsafe-eval and unsafe-inline on script-src — elevated code execution risk.
- dom_sink_innerhtml_userctrl crx rate.js uses innerHTML from variable — DOM-XSS sink; csp_present==true limits severity → +0.5.
- js_external_hosts crx Contacts zenadservices.net (ad-tech), statics.games-storage-aws.yandex.net (RU CDN), github.com, drift-boss.me.
- triple_stale_fingerprint store 31mo stale + MV3 + no CVEs — v2 calibration triple-stale only requires >24mo+CVEs+MV2; partial match, no bonus.
Pillar Scores
Permissions0.00
Reputation7.50
Network2.00
Webstore6.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 05:14
Listing SHA
46ccf3a8564c…
Force block
— not fired
Score recovered
no
Elapsed
—